Security Model Today
Compex’s current security model focuses on controlled execution boundaries, role-separated access, policy-controlled workflows, audit events, and evidence records. It is evaluation-stage and should be reviewed in the context of sandbox and pilot environments.
Current posture
Encrypted storage and transport
Used where implemented in the current environment and validated during pilot setup.
Role-separated access
Data owners, processors, reviewers, and approved users are treated as distinct roles.
Policy-controlled workflows
Workloads and outputs are scoped before execution.
What this means
For business readers, the security model is about making the workflow reviewable. Compex should make it easier to understand who did what, under which policy, and with which outputs.
Current status
Compex is designed for auditability and certification-readiness. The current product is not independently certified.
Limitations
Security posture depends on the deployed environment, identity configuration, data scope, and operational controls. A pilot must document what is implemented and what remains out of scope.